Icon chevron up
Here's a dismissible notice for cookies notices etc.
Dismiss
Server racks in a data centre

Non-Profit IT Assessment

Non-profits are asked to run like enterprises on budgets that do not allow for it. The result is familiar: three or four sites on whatever connection was affordable at the time, a server that has been due for replacement since before the last executive director, and a volunteer roster that turns over faster than anyone can track who still holds a login. The Non-Profit IT Assessment is a free review of exactly that situation, run by NetFusion Designs from 141 Main Street N, Markham.

It produces a written, risk-ranked account of your sites, your access control, your continuity position and your ageing infrastructure. Those are the four things funders increasingly ask about and the four hardest things to fund. There is no charge, and the report is yours to quote from in a grant application if it helps.

What the assessment reviews

Non-profit technology fails differently from corporate technology. It rarely fails because nobody cared. It fails because the money went to programmes, which was the right decision at the time, and nobody wrote down the consequence. The review is aimed at those consequences.

We have done this work. Youth Employment Services replaced ageing servers and moved LeaveTracker onto supportable infrastructure, and the Ontario Soil and Crop Improvement Association moved a multi-branch association into the cloud. Our non-profit IT services page covers how we work with the sector generally.

What comes back to you

The report is written for people who are not technologists and who may need to forward it to a board or funder without editing it first. Every finding gives you what we found, what it puts at risk, what to do, and how urgent it is.

Ranking is done on consequence to the mission rather than on technical severity. A gap that would interrupt a service your clients depend on outranks a theoretical weakness in a system nobody uses.

Fixable with time, not money
  • Accounts belonging to volunteers and staff who left, still active.
  • Multi-factor authentication available on your existing licensing but not turned on.
  • Donor or client exports that nobody reviews or restricts.
  • Backups running without a single tested restore behind them.
  • Administrator rights handed out years ago and never taken back.
Needs a budget line
  • A single unsupported server that several programmes depend on.
  • Branch sites with no meaningful protection or monitoring at all.
  • No documented way to keep services running if a site is unavailable.
  • Overlapping cloud subscriptions nobody owns, costing more than they should.

Findings are not priced and the report is not a proposal. Several items in a typical assessment cost nothing but attention, and we say which ones those are.

The process from first call to recommendations

Four stages. Nothing happens that you have not agreed to, and we work around your programme delivery rather than through it.

1
Discovery call

How many sites, how many staff and volunteers, which systems carry the programmes, what your funders ask you to demonstrate, and what has already gone wrong. We agree the scope in that conversation and confirm what stays out of it.

2
The assessment

We review what you have agreed to show us: site connectivity, identity and access, servers and cloud services, backup and continuity, and how donor and client data moves. Read-only wherever possible, and nothing altered without permission.

3
Findings

We write it up, rank it, and hand it over. The document belongs to you and can go to your board, your funder or another IT provider without any involvement from us.

4
Recommendations

We take you through it and separate the items you can close internally from the ones needing outside help, along with which are worth putting into a funding request.

Where the assessment stops

Being clear about the boundary is part of the offer, not a disclaimer at the bottom of it.

Who benefits, and who needs something different

Two organizations of the same size can need entirely different things. It is worth reading these before booking.

Organizations running more than one site. If you have branches, satellite offices or programme locations, the assessment earns its time simply by showing how unequal those sites are. That imbalance is almost always larger than anyone expects.

Organizations with high volunteer turnover. Where dozens of people come and go each year and access is granted informally, an access review is the single most useful thing an outsider can do for you.

Organizations facing a funder question they cannot answer. If a funding agreement asks about continuity or data handling and the honest answer is that nobody knows, the assessment turns that into something you can respond to with specifics.

Organizations that should ask for something else. A four-person charity working entirely in the cloud does not need this; a short general IT conversation will do. Nor does an organization that already knows its server must be replaced and simply wants that quoted. And if a funder has asked for a formal audit or a penetration test by name, engage the specialist they had in mind.

Questions non-profit leaders ask

Is it genuinely free, and do we have to become a client?

Genuinely free, and no. You keep the report either way. Some organizations engage us for the corrective work, some take the report to the provider they already use, and some do the work themselves with volunteers. All three are fine outcomes.

Can we share the report with our board or a funder?

Yes. It is written on the assumption that you might, which is why it avoids jargon and does not read as a sales document. Share it in whole or in part, with or without telling us.

We have almost no budget. Is there any point?

There usually is. A meaningful share of findings cost nothing to fix, and knowing which risks you are carrying deliberately is worth more than a plan you cannot afford. Where money is genuinely required, having it written down helps make the case.

Our IT is looked after by a volunteer. Will this undermine them?

That is not the intention and need not be the effect. Volunteers running non-profit IT are usually doing well with very little. The report gives them a prioritized list and, frequently, the external backing they have needed to get something approved.

What about the data you see during the review?

We keep access to the minimum needed and agree it with you first. NetFusion Designs is SOC 2 Type 2 attested, and assessment work runs under the same controls as our client work. Ask on the discovery call if you want that confirmed in writing.

Book your Non-Profit IT Assessment

Leave your details and we will arrange the discovery call around your programme schedule. Our helpdesk and Security Operations Centre are staffed around the clock, we target one hour on critical issues, and 95% of tickets are resolved same day. You can also reach us on 647-476-5259.

We respect your privacy. We will not send you marketing you did not ask for.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Close search

Search